CRITICAL9.8CVE-2025-28389Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack. from 0, <= 6.0.0
CRITICAL9.8CVE-2025-28388OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account. from 0, <= 6.0.0
CRITICAL9.8CVE-2025-28386A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers to execute arbitrar… from 0, <= 6.0.0
CRITICAL9.6OpenC3 COSMOS has SQL Injection in QuestDB Time-Series Database
>= 6.7.0, < 7.0.0
CRITICAL9.1OpenC3 COSMOS Vulnerable to Directory Traversal via /script-api/scripts/ endpoint
from 0, <= 6.0.0
HIGH8.1OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
from 0, < 7.0.0
HIGH8.1OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
from 0, < 6.10.5
HIGH7.5OpenC3 COSMOS Vulnerable to Directory Traversal via openc3-api/tables endpoint
from 0, <= 6.0.0
HIGH7.5A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all cont…
from 0, <= 6.0.0
MEDIUM6.5OpenC3 Path Traversal via screen controller (`GHSL-2024-127`)
from 0, < 5.19.0
MEDIUM6.5OpenC3 Path Traversal via screen controller (`GHSL-2024-127`)
from 0, < a34e61aea5a465f0ab3e57d833ae7ff4cafd710b | from 0, < 5.19.0
MEDIUM6.1A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scripts or HTML via inj…
from 0, <= 6.0.0
MEDIUM6.1OpenC3 Cross-site Scripting in Login functionality (`GHSL-2024-128`)
from 0, < 5.19.0
MEDIUM6.1OpenC3 Cross-site Scripting in Login functionality (`GHSL-2024-128`)
from 0, < 762d7e0e93bdc2f340b1e42acccedc78994a576e | from 0, < 5.19.0
MEDIUM5.9OpenC3 stores passwords in clear text (`GHSL-2024-129`)
from 0, < 5.19.0
MEDIUM5.9OpenC3 stores passwords in clear text (`GHSL-2024-129`)
from 0, < b5ab34fe7fa54c0c8171c4aa3caf4e03d6f63bd7 | from 0, < 5.19.0
MEDIUM4.6OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
from 0, < 7.0.0
MEDIUM4.6OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
from 0, < 7.0.0
MEDIUM4.3OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
from 0, < 6.10.5